UK GDPR applies to almost every UK business — anyone processing personal data of customers, suppliers, employees, or prospects. The eight-point compliance baseline: identify lawful bases, publish a privacy notice, register with the ICO, get consent right, respond to subject access requests, manage breaches, train staff, and document everything.
This guide covers the practical minimum. Most UK SMEs that follow these steps meet the substantive requirements of UK GDPR and the Data Protection Act 2018.
1. Identify your lawful bases for processing
Every act of personal data processing needs a lawful basis. There are six:
- Consent — the person has given clear, freely-given, informed consent.
- Contract — processing is necessary to perform a contract with the person, or to take steps before entering one.
- Legal obligation — processing is necessary to comply with a law.
- Vital interests — processing is necessary to protect someone''s life (rare).
- Public task — processing is necessary for an official function (rare in commercial businesses).
- Legitimate interests — processing is necessary for your legitimate interest, balanced against the individual''s rights.
Most UK SME processing falls under: Contract (fulfilling orders, customer support), Legitimate Interests (B2B marketing, fraud prevention), Legal Obligation (payroll, tax records), and Consent (only when the others don''t fit — e.g. marketing email to prospects).
For each significant processing activity, identify the basis and document it. Special category data (health, race, religion, biometrics) needs both a lawful basis AND a separate special-category condition.
2. Publish a clear privacy notice
A privacy notice tells people:
- Who you are and how to contact you.
- What personal data you collect and why.
- The lawful basis for each processing purpose.
- Who you share data with.
- How long you keep it.
- The international transfers you make and the safeguards.
- Their rights and how to exercise them.
- How to complain to the ICO.
Publish on your website, link from every form that collects data, and update when things change. A template like our Privacy notice template covers the standard SME processing.
3. Register with the ICO and pay the data protection fee
Most UK businesses processing personal data must register with the ICO and pay an annual fee (£40-£2,900 depending on size). This is a strict-liability obligation — failure to register triggers a fixed penalty up to £4,350, regardless of whether you''ve done anything else wrong.
Check the ICO''s self-assessment tool to confirm you need to register and which tier applies.
4. Get consent right when you need it
Consent under UK GDPR is much stricter than the old "implied consent" model. Valid consent must be:
- Freely given — no pressure or bundled-into-terms-and-conditions.
- Specific — for a defined purpose.
- Informed — the person knows what they''re consenting to.
- Unambiguous — a clear affirmative action (a tick-box that''s not pre-ticked, an explicit "Yes I want to receive marketing").
- Withdrawable — and as easy to withdraw as to give.
Use consent when: sending B2C marketing emails to non-customers, deploying non-essential cookies, processing special category data without another basis.
Don''t use consent when another basis works — Contract or Legitimate Interests are usually more reliable.
5. Respond to data subject rights requests within 30 days
UK GDPR gives individuals 8 rights. The most common requests:
- Subject Access Request (SAR) — give the person a copy of all their personal data you hold.
- Right to rectification — correct inaccurate data.
- Right to erasure ("right to be forgotten") — delete the data, subject to exceptions.
- Right to object — particularly to direct marketing (an absolute right).
- Right to data portability — give the data to them in a portable format.
All requests must be responded to within 30 calendar days from receipt (extendable by 60 days for complex requests, with notice to the requester). Use our SAR response process template for the workflow.
6. Have a breach response plan
A personal data breach is any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Examples: a laptop with customer data is stolen, an employee accidentally emails a spreadsheet to the wrong recipient, a database is hacked, a member of staff inappropriately accesses HR records.
Plan:
- Detect: have logging and alerting in place to spot breaches.
- Contain: isolate the affected systems / data.
- Assess: what data, how many people, what risk to them.
- Report: to the ICO within 72 hours of becoming aware, IF the breach is likely to result in a risk to people''s rights and freedoms.
- Notify affected individuals if the breach is likely to result in HIGH risk.
- Document: every breach, whether reported or not.
72 hours is fast — make sure the process is rehearsed before you need it.
7. Train staff
Most data breaches in UK SMEs are human error (mis-sent emails, lost laptops, weak passwords). Annual training for everyone who handles personal data is a basic control:
- What is personal data and why does it matter.
- The lawful bases briefly.
- How to handle data subject requests.
- What to do in a breach (escalate, don''t try to fix it alone).
- Strong passwords, phishing recognition, device security.
Document who got trained and when. The ICO asks on inspection.
8. Document everything
Article 30 of UK GDPR requires a "record of processing activities" (ROPA) — a document listing every processing purpose, lawful basis, categories of data, recipients, retention, international transfers, and security measures.
Small organisations (under 250 employees) have a narrower obligation, but should still document the substantive processing activities — both for compliance and to make the ICO inspection painless.
Additional considerations
Appointing a Data Protection Officer (DPO)
A DPO is mandatory if you''re a public authority, do large-scale systematic monitoring, or process special category data on a large scale. Most SMEs don''t need a DPO — but if you''re considering one (or an outsourced DPO-as-a-service), document the role and ensure independence.
International transfers
Transferring personal data outside the UK requires a safeguard — typically Standard Contractual Clauses, an adequacy decision (e.g. EU, EEA, certain other countries), or Binding Corporate Rules. The US is partially covered by the UK extension of the EU-US Data Privacy Framework for participating organisations.
Children''s data
Different rules apply for processing children''s personal data. UK age of digital consent is 13. Marketing to under-18s in particular triggers heightened protections.
What to do this month
- Run through this 8-point list against your current practice. Most SMEs have gaps in 3-4 points.
- Update or publish your privacy notice.
- Register with the ICO if you haven''t.
- Set up a simple ROPA — even a Google Sheet with 1 row per processing activity is far better than nothing.
- Schedule annual GDPR awareness training for the team.